Overview
Overnight, thousands of unauthorised card transactions were processed through EDC/POS terminals and approved by the issuing bank, including transactions from cards that should have been declined.
DFI was appointed to find out how. Our investigation uncovered a terminal patch manipulation and a terminal gap in how card transactions were validated, and anomalous activity in data to the voucher processing environment during the attack window. Forensic analysis revealed how bypasses identified how the fraud was carried out.
Attack chain
Six stages, reconstructed from forensic evidence.
Actor
TTP: how the attack worked
Mapped to MITRE ATT&CK for Enterprise, to benchmark attack-level detection coverage.
IoC: what to look for
Behavioural indicators that can be turned into monitoring rules. Match to system behaviours, not just static signatures.
Card transactions approved despite failed or missing cardholder verification.
Repeated cryptographic values across different transactions or terminals.
Expired or invalid cards approved offline.
Transactions system amount isolations or batching on overnight bursted card transactions.